BREACH WATCH BRIEF Critical ☁️ Vulnerability

Critical Deserialization, SSRF, and Hard‑Coded Credential Flaws in Grid Protection Alliance openPDC/openHistorian

CISA reports six CVEs (CVSS 9.8) in openPDC and openHistorian that enable unauthenticated attackers to execute arbitrary code or perform SSRF. The flaws test the control objective of secure software lifecycle management, a key trust signal for energy‑sector auditors.

SeverityCritical
Type☁️ Vulnerability
ConfidenceHigh
ReportedOct 8, 2026
Energy & Utilities Energy utilities and grid operators using openPDC/openHistorian Vulnerability Exploit

What happened

OpenPDC versions <2.9.482 and openHistorian versions <2.8.585 contain unsafe deserialization, missing authentication, SSRF, hard‑coded credentials, and unsafe reflection. An unauthenticated network attacker can exploit these to run arbitrary code on the host system.

Why it matters for trust and compliance

  • The incident highlights the need for continuous vulnerability monitoring and evidence of timely patching—core to the control objective of secure software development and a demonstrable audit trail under NIST CSF 2.0.
  • Shows the importance of continuous vulnerability scanning and patch‑management evidence for audit readiness.
  • Supports the control objective of secure software lifecycle, satisfying multiple frameworks through a single control.

Who is affected

Energy utilities and grid operators using openPDC/openHistorian

Recommended actions

  1. Upgrade openPDC to ≥ 2.9.482 and openHistorian to ≥ 2.8.585.
  2. Enforce Windows Authentication on all console interfaces.
  3. Run a full vulnerability scan on grid‑control assets and remediate any findings.
  4. Record patch‑deployment dates and configuration changes in your continuous monitoring platform.

Details

CVEs
CVE-2026-104629, CVE-2026-100730, CVE-2026-105281, CVE-2026-85479, CVE-2026-101022, CVE-2026-105278

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.